![]() |
| |||||||
Log-Analyse und Auswertung: Rechner extrem Langsam. Troz Registry und Festplattenbereinigung.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #1 |
| | Rechner extrem Langsam. Troz Registry und Festplattenbereinigung. Hallo Leute, ich bin neu hier. Seit ein Paar tagen ist mein Rechner extrem langsam. Ich habe ihn mit CCleaner bereinigt (Registry und Festpaltte) und mit Defraggler Defragmentiert. Leider hat das nichts gebracht. Ich hab jetzt mal Combofix drüberlaufen lassen. Hier der Log: Code:
ATTFilter ComboFix 11-07-02.03 - Sascha 03.07.2011 16:33:56.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.2047.659 [GMT 2:00]
ausgeführt von:: c:\users\Sascha\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\facemoods.com
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoods.crx
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoods.png
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsApp.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsEng.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll
c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\uninstall.exe
c:\windows\SysWow64\html
c:\windows\SysWow64\html\calendar.html
c:\windows\SysWow64\html\calendarbottom.html
c:\windows\SysWow64\html\calendartop.html
c:\windows\SysWow64\html\crystalexportdialog.htm
c:\windows\SysWow64\html\crystalprinthost.html
c:\windows\SysWow64\images
c:\windows\SysWow64\images\toolbar\calendar.gif
c:\windows\SysWow64\images\toolbar\crlogo.gif
c:\windows\SysWow64\images\toolbar\export.gif
c:\windows\SysWow64\images\toolbar\export_over.gif
c:\windows\SysWow64\images\toolbar\exportd.gif
c:\windows\SysWow64\images\toolbar\First.gif
c:\windows\SysWow64\images\toolbar\first_over.gif
c:\windows\SysWow64\images\toolbar\Firstd.gif
c:\windows\SysWow64\images\toolbar\gotopage.gif
c:\windows\SysWow64\images\toolbar\gotopage_over.gif
c:\windows\SysWow64\images\toolbar\gotopaged.gif
c:\windows\SysWow64\images\toolbar\grouptree.gif
c:\windows\SysWow64\images\toolbar\grouptree_over.gif
c:\windows\SysWow64\images\toolbar\grouptreed.gif
c:\windows\SysWow64\images\toolbar\grouptreepressed.gif
c:\windows\SysWow64\images\toolbar\Last.gif
c:\windows\SysWow64\images\toolbar\last_over.gif
c:\windows\SysWow64\images\toolbar\Lastd.gif
c:\windows\SysWow64\images\toolbar\Next.gif
c:\windows\SysWow64\images\toolbar\next_over.gif
c:\windows\SysWow64\images\toolbar\Nextd.gif
c:\windows\SysWow64\images\toolbar\Prev.gif
c:\windows\SysWow64\images\toolbar\prev_over.gif
c:\windows\SysWow64\images\toolbar\Prevd.gif
c:\windows\SysWow64\images\toolbar\print.gif
c:\windows\SysWow64\images\toolbar\print_over.gif
c:\windows\SysWow64\images\toolbar\printd.gif
c:\windows\SysWow64\images\toolbar\Refresh.gif
c:\windows\SysWow64\images\toolbar\refresh_over.gif
c:\windows\SysWow64\images\toolbar\refreshd.gif
c:\windows\SysWow64\images\toolbar\Search.gif
c:\windows\SysWow64\images\toolbar\search_over.gif
c:\windows\SysWow64\images\toolbar\searchd.gif
c:\windows\SysWow64\images\toolbar\up.gif
c:\windows\SysWow64\images\toolbar\up_over.gif
c:\windows\SysWow64\images\toolbar\upd.gif
c:\windows\SysWow64\images\tree\begindots.gif
c:\windows\SysWow64\images\tree\beginminus.gif
c:\windows\SysWow64\images\tree\beginplus.gif
c:\windows\SysWow64\images\tree\blank.gif
c:\windows\SysWow64\images\tree\blankdots.gif
c:\windows\SysWow64\images\tree\dots.gif
c:\windows\SysWow64\images\tree\lastdots.gif
c:\windows\SysWow64\images\tree\lastminus.gif
c:\windows\SysWow64\images\tree\lastplus.gif
c:\windows\SysWow64\images\tree\Magnify.gif
c:\windows\SysWow64\images\tree\minus.gif
c:\windows\SysWow64\images\tree\minusbox.gif
c:\windows\SysWow64\images\tree\plus.gif
c:\windows\SysWow64\images\tree\plusbox.gif
c:\windows\SysWow64\images\tree\singleminus.gif
c:\windows\SysWow64\images\tree\singleplus.gif
L:\install.exe
.
.
((((((((((((((((((((((( Dateien erstellt von 2011-06-03 bis 2011-07-03 ))))))))))))))))))))))))))))))
.
.
2011-07-03 15:08 . 2011-07-03 15:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-03 14:25 . 2011-07-03 14:25 -------- d-----w- c:\users\Sascha\AppData\Roaming\Adobe Mini Bridge CS5
2011-07-03 14:25 . 2011-07-03 14:25 -------- d-----w- c:\users\Sascha\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2011-07-03 13:54 . 2011-06-07 17:10 8873296 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AC003413-65E3-4156-A6FD-B2556C23EF79}\mpengine.dll
2011-06-29 15:10 . 2011-06-29 15:10 -------- d-----w- c:\program files\CCleaner
2011-06-29 12:44 . 2011-05-24 11:42 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 12:44 . 2011-05-24 10:40 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-06-29 12:44 . 2011-05-24 10:40 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-06-29 12:44 . 2011-05-24 10:39 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-06-29 12:44 . 2011-05-24 10:37 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-06-24 11:54 . 2011-06-24 12:07 -------- d-----w- c:\users\Sascha\workspace
2011-06-23 21:11 . 2011-06-24 12:14 -------- d-----w- c:\users\Sascha\.android
2011-06-23 21:11 . 2011-06-23 21:11 -------- d-----w- c:\program files (x86)\Android
2011-06-23 21:08 . 2011-06-23 21:08 525544 ----a-w- c:\windows\system32\deployJava1.dll
2011-06-23 21:07 . 2011-06-23 21:08 -------- d-----w- c:\program files\Java
2011-06-23 21:05 . 2011-06-24 12:13 -------- d-----w- c:\program files (x86)\eclipse
2011-06-23 17:29 . 2011-06-23 17:29 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll
2011-06-23 17:29 . 2011-06-23 17:29 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll
2011-06-22 18:29 . 2011-06-22 18:29 -------- d-----w- c:\programdata\Microsoft Visual Studio
2011-06-21 12:55 . 2011-06-21 12:55 -------- d-----w- c:\programdata\ATI
2011-06-21 12:55 . 2011-06-21 12:55 -------- d-----w- c:\program files (x86)\AMD APP
2011-06-19 19:02 . 2011-06-06 16:36 4005936 ----a-w- c:\windows\SysWow64\GameMon.des
2011-06-19 19:02 . 2005-01-02 03:43 4682 ----a-w- c:\windows\SysWow64\npptNT2.sys
2011-06-19 19:02 . 2003-07-18 12:17 5174 ----a-w- c:\windows\SysWow64\nppt9x.vxd
2011-06-19 19:02 . 2011-06-19 19:02 -------- d-----w- c:\program files\Common Files\INCA Shared
2011-06-18 13:17 . 2011-06-18 13:17 -------- d-----w- C:\fd9e99b99c003c1c8dfcf210c70e
2011-06-17 20:33 . 2011-06-17 20:34 -------- d-----w- c:\users\Sascha\AppData\Roaming\Trillian
2011-06-17 20:33 . 2011-06-17 20:33 -------- d-----w- c:\program files (x86)\Trillian
2011-06-17 11:30 . 2011-06-17 11:32 -------- d-----w- c:\program files (x86)\Gabelstapler Simulator 2009
2011-06-17 11:29 . 2000-08-19 17:29 268048 ----a-w- c:\windows\SysWow64\dxtmeta2.dll
2011-06-16 18:14 . 2011-04-25 05:33 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-16 18:14 . 2011-04-25 02:34 499200 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-16 18:14 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-16 18:14 . 2011-04-27 02:39 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 18:14 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 18:14 . 2011-05-28 03:06 3135488 ----a-w- c:\windows\system32\win32k.sys
2011-06-16 18:14 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-16 18:14 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-16 18:14 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-16 18:14 . 2011-02-25 06:22 861696 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-16 18:14 . 2011-02-25 05:34 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-16 18:14 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-16 18:14 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-16 13:58 . 2011-06-19 14:08 -------- d-----w- C:\HammerAutosave
2011-06-16 12:51 . 2011-06-16 13:01 -------- d-----w- c:\programdata\TrackMania
2011-06-15 19:38 . 2011-06-15 19:38 -------- d-----w- c:\program files (x86)\Pokemon World Online
2011-06-15 16:36 . 2011-06-15 16:36 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-06-15 16:36 . 2011-06-15 16:36 -------- d-----w- c:\program files (x86)\Common Files\Microsoft Games
2011-06-15 16:24 . 2011-06-15 16:24 -------- d-----w- c:\program files (x86)\Microsoft Games
2011-06-14 19:36 . 2011-07-03 14:05 -------- d-----w- c:\users\Sascha\AppData\Roaming\skypePM
2011-06-14 19:36 . 2011-06-30 15:41 -------- d-----w- c:\programdata\Skype Extras
2011-06-14 19:32 . 2011-07-03 15:05 -------- d-----w- c:\users\Sascha\AppData\Roaming\Skype
2011-06-14 19:31 . 2011-06-14 19:31 -------- d-----w- c:\program files (x86)\Common Files\Skype
2011-06-14 19:31 . 2011-06-14 19:32 -------- d-----r- c:\program files (x86)\Skype
2011-06-14 19:31 . 2011-06-14 19:31 -------- d-----w- c:\programdata\Skype
2011-06-14 14:03 . 2011-06-14 15:01 -------- d-----w- c:\program files (x86)\Just Cause 2
2011-06-12 11:14 . 2011-06-12 11:14 -------- d-----w- c:\users\Sascha\AppData\Local\SKIDROW
2011-06-11 14:00 . 2011-06-11 14:00 -------- d-----w- c:\program files (x86)\Valve
2011-06-06 14:13 . 2011-06-06 14:13 -------- d-----w- C:\MyMod
2011-06-06 10:50 . 2011-06-06 10:50 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2011-06-05 18:02 . 2011-06-05 18:02 -------- d-sh--w- c:\programdata\DSS
2011-06-05 18:02 . 2011-06-05 18:02 -------- d-----w- c:\programdata\Codemasters
2011-06-05 18:00 . 2011-03-19 13:16 1417216 ----a-w- c:\windows\SysWow64\rapture3d_oal.dll
2011-06-05 18:00 . 2010-09-22 11:12 19087360 ----a-w- c:\windows\SysWow64\mkl_blueripple.dll
2011-06-05 18:00 . 2011-06-05 18:00 -------- d-----w- c:\program files (x86)\BRS
2011-06-05 18:00 . 2011-06-05 18:00 -------- d-----w- c:\program files (x86)\OpenAL
2011-06-05 18:00 . 2011-04-15 23:40 809496 ----a-r- c:\windows\SysWow64\tmp3093.tmp
2011-06-05 17:51 . 2011-06-05 17:51 -------- d-----w- c:\program files (x86)\Codemasters
2011-06-05 10:23 . 2011-06-05 10:23 -------- d-----w- c:\users\Sascha\AppData\Local\Activision
2011-06-05 09:44 . 2007-10-24 21:12 18853376 ----a-r- c:\program files (x86)\CryEngine(R)2 Sandbox(TM)2.msi
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-21 12:50 . 2011-04-20 02:30 23336960 ----a-w- c:\windows\system32\atio6axx.dll
2011-06-21 12:49 . 2011-04-20 01:27 58880 ----a-w- c:\windows\system32\coinst.dll
2011-06-21 12:49 . 2011-04-20 01:22 14848 ----a-w- c:\windows\system32\atig6pxx.dll
2011-06-21 12:49 . 2011-04-20 01:30 4017152 ----a-w- c:\windows\SysWow64\atiumdva.dll
2011-06-21 12:49 . 2011-04-20 01:23 366592 ----a-w- c:\windows\system32\atiadlxx.dll
2011-06-21 12:49 . 2011-04-20 01:21 40960 ----a-w- c:\windows\system32\atiuxp64.dll
2011-06-21 12:49 . 2011-04-20 02:07 811008 ----a-w- c:\windows\system32\aticfx64.dll
2011-06-21 12:49 . 2011-04-20 01:38 4330496 ----a-w- c:\windows\SysWow64\atiumdag.dll
2011-06-21 12:49 . 2011-04-20 02:09 688128 ----a-w- c:\windows\SysWow64\aticfx32.dll
2011-06-21 12:49 . 2011-04-20 01:49 5008384 ----a-w- c:\windows\system32\atidxx64.dll
2011-06-21 12:49 . 2011-04-20 01:21 29184 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2011-06-21 12:49 . 2011-04-20 01:22 39936 ----a-w- c:\windows\system32\atig6txx.dll
2011-06-16 19:04 . 2011-05-11 15:09 2478272 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2011-06-16 11:46 . 2011-05-25 15:29 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-07 17:10 . 2011-05-15 14:49 8873296 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-06-05 18:04 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2011-06-05 18:04 . 2009-08-18 09:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-06-05 18:00 . 2011-05-25 15:15 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2011-06-05 18:00 . 2011-05-25 15:15 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-06-05 18:00 . 2011-05-25 15:15 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2011-06-05 18:00 . 2011-05-25 15:15 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-05-24 21:44 . 2011-05-24 21:44 61952 ----a-w- c:\windows\system32\OVDecode64.dll
2011-05-24 21:44 . 2011-05-24 21:44 59904 ----a-w- c:\windows\SysWow64\OVDecode.dll
2011-05-24 21:44 . 2011-05-24 21:44 16672768 ----a-w- c:\windows\system32\amdocl64.dll
2011-05-24 21:43 . 2011-05-24 21:43 12798976 ----a-w- c:\windows\SysWow64\amdocl.dll
2011-05-11 19:27 . 2011-05-11 19:27 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-05-10 20:36 . 2011-05-10 20:36 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2011-05-10 20:36 . 2011-05-10 20:36 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2011-05-10 20:36 . 2011-05-10 20:36 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-05-10 20:36 . 2011-05-10 20:36 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2011-05-10 20:36 . 2011-05-10 20:36 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2011-05-10 20:36 . 2011-05-10 20:36 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2011-05-10 20:36 . 2011-05-10 20:36 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2011-05-10 20:36 . 2011-05-10 20:36 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2011-05-10 20:36 . 2011-05-10 20:36 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2011-05-10 20:36 . 2011-05-10 20:36 367104 ----a-w- c:\windows\SysWow64\html.iec
2011-05-10 20:36 . 2011-05-10 20:36 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2011-05-10 20:36 . 2011-05-10 20:36 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2011-05-10 20:36 . 2011-05-10 20:36 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2011-05-10 20:36 . 2011-05-10 20:36 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2011-05-10 20:36 . 2011-05-10 20:36 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2011-05-10 20:36 . 2011-05-10 20:36 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-05-10 20:36 . 2011-05-10 20:36 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2011-05-10 20:36 . 2011-05-10 20:36 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2011-05-10 20:36 . 2011-05-10 20:36 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2011-05-10 20:36 . 2011-05-10 20:36 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-10 20:36 . 2011-05-10 20:36 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-10 20:36 . 2011-05-10 20:36 49664 ----a-w- c:\windows\system32\imgutil.dll
2011-05-10 20:36 . 2011-05-10 20:36 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-10 20:36 . 2011-05-10 20:36 222208 ----a-w- c:\windows\system32\msls31.dll
2011-05-10 20:36 . 2011-05-10 20:36 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-10 20:36 . 2011-05-10 20:36 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-05-10 20:36 . 2011-05-10 20:36 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-10 20:36 . 2011-05-10 20:36 12288 ----a-w- c:\windows\system32\mshta.exe
2011-05-10 20:36 . 2011-05-10 20:36 114176 ----a-w- c:\windows\system32\admparse.dll
2011-05-10 20:36 . 2011-05-10 20:36 111616 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-10 20:36 . 2011-05-10 20:36 85504 ----a-w- c:\windows\system32\iesetup.dll
2011-05-10 20:36 . 2011-05-10 20:36 76800 ----a-w- c:\windows\system32\tdc.ocx
2011-05-10 20:36 . 2011-05-10 20:36 603648 ----a-w- c:\windows\system32\vbscript.dll
2011-05-10 20:36 . 2011-05-10 20:36 448512 ----a-w- c:\windows\system32\html.iec
2011-05-10 20:36 . 2011-05-10 20:36 30720 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-10 20:36 . 2011-05-10 20:36 165888 ----a-w- c:\windows\system32\iexpress.exe
2011-05-10 20:36 . 2011-05-10 20:36 160256 ----a-w- c:\windows\system32\wextract.exe
2011-05-10 20:36 . 2011-05-10 20:36 1492992 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-10 19:34 . 2011-05-10 19:34 374792 ----a-w- c:\windows\system32\drivers\UMDF\lgSSQVGA.dll
2011-05-10 19:34 . 2011-05-10 19:34 157704 ----a-w- c:\windows\system32\drivers\UMDF\lgSSBW.dll
2011-05-10 19:34 . 2011-05-10 19:34 22408 ----a-w- c:\windows\system32\drivers\LGBusEnum.sys
2011-05-10 19:34 . 2011-05-10 19:34 16008 ----a-w- c:\windows\system32\drivers\LGVirHid.sys
2011-05-10 19:34 . 2011-05-10 19:34 30728 ----a-w- c:\windows\system32\drivers\LGPBTDD.sys
2011-05-10 19:33 . 2011-05-10 19:33 53248 ----a-r- c:\users\Sascha\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-05-10 19:33 . 2011-05-10 19:33 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-04-22 11:09 . 2011-04-22 11:09 1858384 ----a-w- c:\windows\system32\msvcr100d.dll
2011-04-22 11:09 . 2011-04-22 11:09 1014096 ----a-w- c:\windows\system32\msvcp100d.dll
2011-04-22 11:03 . 2011-04-22 11:03 9032016 ----a-w- c:\windows\system32\mfc100ud.dll
2011-04-22 11:03 . 2011-04-22 11:03 8955728 ----a-w- c:\windows\system32\mfc100d.dll
2011-04-22 11:03 . 2011-04-22 11:03 120144 ----a-w- c:\windows\system32\mfcm100ud.dll
2011-04-22 11:03 . 2011-04-22 11:03 118608 ----a-w- c:\windows\system32\mfcm100d.dll
2011-04-22 10:58 . 2011-04-22 10:58 106832 ----a-w- c:\windows\system32\vcomp100d.dll
2011-04-22 10:15 . 2011-04-22 10:15 87888 ----a-w- c:\windows\SysWow64\vcomp100d.dll
2011-04-22 10:15 . 2011-04-22 10:15 80720 ----a-w- c:\windows\SysWow64\mfcm100u.dll
2011-04-22 10:15 . 2011-04-22 10:15 80208 ----a-w- c:\windows\SysWow64\mfcm100.dll
2011-04-22 10:15 . 2011-04-22 10:15 768848 ----a-w- c:\windows\SysWow64\msvcr100.dll
2011-04-22 10:15 . 2011-04-22 10:15 743248 ----a-w- c:\windows\SysWow64\msvcp100d.dll
2011-04-22 10:15 . 2011-04-22 10:15 6994256 ----a-w- c:\windows\SysWow64\mfc100ud.dll
2011-04-22 10:15 . 2011-04-22 10:15 6926672 ----a-w- c:\windows\SysWow64\mfc100d.dll
2011-04-22 10:15 . 2011-04-22 10:15 64336 ----a-w- c:\windows\SysWow64\mfc100fra.dll
2011-04-22 10:15 . 2011-04-22 10:15 64336 ----a-w- c:\windows\SysWow64\mfc100deu.dll
2011-04-22 10:15 . 2011-04-22 10:15 63824 ----a-w- c:\windows\SysWow64\mfc100esn.dll
2011-04-22 10:15 . 2011-04-22 10:15 62288 ----a-w- c:\windows\SysWow64\mfc100ita.dll
2011-04-22 10:15 . 2011-04-22 10:15 60752 ----a-w- c:\windows\SysWow64\mfc100rus.dll
2011-04-22 10:15 . 2011-04-22 10:15 55120 ----a-w- c:\windows\SysWow64\mfc100enu.dll
2011-04-22 10:15 . 2011-04-22 10:15 51024 ----a-w- c:\windows\SysWow64\vcomp100.dll
2011-04-22 10:15 . 2011-04-22 10:15 43856 ----a-w- c:\windows\SysWow64\mfc100jpn.dll
2011-04-22 10:15 . 2011-04-22 10:15 4368720 ----a-w- c:\windows\SysWow64\mfc100u.dll
2011-04-22 10:15 . 2011-04-22 10:15 4342600 ----a-w- c:\windows\SysWow64\mfc100.dll
2011-04-22 10:15 . 2011-04-22 10:15 43344 ----a-w- c:\windows\SysWow64\mfc100kor.dll
2011-04-22 10:15 . 2011-04-22 10:15 421200 ----a-w- c:\windows\SysWow64\msvcp100.dll
2011-04-22 10:15 . 2011-04-22 10:15 36176 ----a-w- c:\windows\SysWow64\mfc100cht.dll
2011-04-22 10:15 . 2011-04-22 10:15 36176 ----a-w- c:\windows\SysWow64\mfc100chs.dll
2011-04-22 10:15 . 2011-04-22 10:15 1497936 ----a-w- c:\windows\SysWow64\msvcr100d.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-05-10 1242448]
"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2009-11-15 33120]
"AlSrvN"="c:\program files (x86)\Alcohol Soft\Alcohol 120\Plugins\Helper\AlSrvN.exe" [2010-02-06 53760]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-05-26 15147400]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"vmware-tray"="c:\program files (x86)\VMware\VMware Workstation\vmware-tray.exe" [2011-03-25 129648]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-03-02 1310720]
"Ai Nap"="c:\program files (x86)\ASUS\AI Suite\AiNap\AiNap.exe" [2009-03-27 1431040]
"QFan Help"="c:\program files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe" [2009-04-30 598528]
"Cpu Level Up help"="c:\program files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-05-24 336384]
.
c:\users\Sascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Trillian.lnk - c:\program files (x86)\Trillian\trillian.exe [2011-5-18 676352]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\steam\steamapps\common\ava\Binaries\GameGuard\dump_wmimmc.sys [x]
R3 ENTECH64;ENTECH64;c:\windows\system32\DRIVERS\ENTECH64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-03-17 68440]
R3 xpvcom;XPVCOM Port;c:\windows\system32\Drivers\xpvcom.sys [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [x]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2010-09-17 430424]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-03-25 539248]
S2 WPhoneRAPI;Windows Phone RAPI Connectivity Service;c:\program files (x86)\Windows Phone\WPhoneRAPI.exe [2009-08-11 78032]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [x]
S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [x]
S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\DRIVERS\LVUSBS64.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 rt61x64;RT61 Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr6164.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2010-11-16 104008]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
"LXCGCATS"="c:\windows\system32\spool\DRIVERS\x64\3\LXCGtime.dll" [2007-02-22 28672]
"lxcgmon.exe"="c:\program files (x86)\Lexmark 2300 Series\lxcgmon.exe" [2007-04-29 205744]
"EzPrint"="c:\program files (x86)\Lexmark 2300 Series\ezprint.exe" [2007-04-29 103344]
"SoundMAX"="c:\program files (x86)\Analog Devices\SoundMAX\soundmax.exe" [2008-09-24 3862528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.facemoods.com/?a=ddrnw
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files (x86)\VMware\VMware Workstation\vsocklib.dll
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Sascha\AppData\Roaming\Mozilla\Firefox\Profiles\jfc4cuai.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\bh\facemoods.dll
Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodsTlbr.dll
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKLM-Run-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]
@Denied: (A) (Everyone)
"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]
"Key"="ActionsPane"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2011-07-03 17:12:58
ComboFix-quarantined-files.txt 2011-07-03 15:12
.
Vor Suchlauf: 17 Verzeichnis(se), 130.111.008.768 Bytes frei
Nach Suchlauf: 21 Verzeichnis(se), 129.801.007.104 Bytes frei
.
- - End Of File - - 83B2AE53A214570F14981453847E9F6D
![]() Greez, ExEcutAblE |
| Themen zu Rechner extrem Langsam. Troz Registry und Festplattenbereinigung. |
| acrobat update, adobe, asus, combofix, cpu, dateien, defender, device driver, festplatte, firefox, generic, helper, launch, log, microsoft security, microsoft security essentials, mozilla, mp3, neu, nvidia, object, performance, registry, security, software, sptd.sys, start menu, system, system32, syswow64, updates, windows, windows 7 ultimate, wireless |